Learn about CVE-2020-3120, a high-severity vulnerability in Cisco IOS XR Software that allows adjacent attackers to cause a denial of service condition by reloading affected devices.
A vulnerability in the Cisco Discovery Protocol implementation for Cisco FXOS Software, Cisco IOS XR Software, and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition by reloading an affected device.
Understanding CVE-2020-3120
This CVE involves a vulnerability in the Cisco Discovery Protocol implementation that could lead to a DoS attack on affected devices.
What is CVE-2020-3120?
The vulnerability allows an unauthenticated attacker in the same broadcast domain as the affected device to send a malicious Cisco Discovery Protocol packet, causing the device to reload due to memory exhaustion.
The Impact of CVE-2020-3120
Technical Details of CVE-2020-3120
This section provides technical details of the vulnerability.
Vulnerability Description
The vulnerability is caused by a missing check in the affected software when processing Cisco Discovery Protocol messages, allowing an attacker to exploit it through a malicious packet.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from this vulnerability requires immediate steps and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates